File tree
3,386 files changed
+238226
-94992
lines changed- .github
- workflows
- config
- cpp
- autobuilder/Semmle.Autobuild.Cpp.Tests
- downgrades
- 5b388693c66db1e7dc2e76a90aa67a2b6eb74f0f
- 8cba93a44180e0d50a80a660950800d822b981fc
- f79ce79e3b751aeeed59e594633ba5c07a27ef3e
- ql
- lib
- change-notes
- released
- semmle/code/cpp
- commons
- controlflow
- internal
- exprs
- internal
- ir
- dataflow
- internal
- implementation/raw/internal
- models
- implementations
- interfaces
- rangeanalysis
- new
- internal/semantic
- analysis
- security/InvalidPointerDereference
- valuenumbering
- upgrades
- 5b388693c66db1e7dc2e76a90aa67a2b6eb74f0f
- dbe9c8eb5fc6f54b7ae08c7317d0795b24961564
- f79ce79e3b751aeeed59e594633ba5c07a27ef3e
- src
- Likely Bugs
- Memory Management
- Microsoft
- Security/CWE
- CWE-079
- CWE-119
- CWE-120
- CWE-193
- CWE-497
- change-notes
- released
- test
- examples/expressions
- experimental
- library-tests/rangeanalysis/signanalysis
- query-tests/Security/CWE/CWE-193
- array-access
- constant-size
- library-tests
- access/FieldAccess
- attributes/deprecated_with_msg
- dataflow
- dataflow-tests
- fields
- source-sink-tests
- taint-tests
- ir
- ir
- modulus-analysis
- range-analysis
- sign-analysis
- syntax-zoo
- templates/type_instantiations
- type_sizes
- unspecified_type/types
- valuenumbering/GlobalValueNumbering
- variables/variables
- query-tests
- Critical/MemoryFreed
- Security/CWE
- CWE-078/semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114/semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-120/semmle/tests
- CWE-134/semmle/argv
- CWE-190/semmle/TaintedAllocationSize
- CWE-193
- CWE-457/semmle/tests
- CWE-497/semmle/tests
- CWE-611
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- documentation/library-coverage
- downgrades
- 1f291d4f424b498e7500c0359ca1fe030628a448
- cc2eccd6026e5405594b75eb9d2d3f4646747ccd
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp/Entities
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities/Base
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- examples/snippets
- integration-tests
- all-platforms
- autobuild
- diag_recursive_generics
- standalone_dependencies_net48
- posix-only
- dotnet_test
- standalone_dependencies_multi_target
- standalone_dependencies_nuget
- standalone_dependencies
- windows-only/standalone_dependencies
- lib
- Linq
- change-notes
- released
- ext
- generated
- semmle/code
- asp
- cil
- csharp
- commons
- controlflow/internal
- dataflow
- internal
- rangeanalysis
- exprs
- frameworks
- microsoft
- system
- collections
- data
- linq
- runtime
- security/cryptography
- text
- threading
- test
- security
- auth
- cryptography
- dataflow
- flowsinks
- flowsources
- xml
- serialization
- dotnet
- upgrades
- 585d6402ff8ba3d15114a869d205bdf6d4e0aa3f
- cc2eccd6026e5405594b75eb9d2d3f4646747ccd
- src
- API Abuse
- Bad Practices
- Naming Conventions
- Concurrency
- Dead Code
- Documentation
- Input Validation
- Likely Bugs
- Collections
- LeapYear
- Metrics/Summaries
- Security Features
- CWE-091
- CWE-114
- CWE-327
- CWE-384
- Stubs
- Telemetry
- change-notes
- released
- experimental
- CWE-918
- Security Features
- CWE-327/Azure
- CWE-759
- JsonWebTokenHandler
- Serialization
- backdoor
- ir
- implementation/raw/internal/desugar
- internal
- meta/frameworks
- utils
- modelconverter
- modeleditor
- modelgenerator/internal
- test
- TestUtilities
- library-tests
- assemblies
- assignables
- async
- attributes
- cil
- attributes
- consistency
- dataflow
- enums
- functionPointers
- init-only-prop
- regressions
- typeAnnotations
- comments
- commons/Disposal
- constructors
- conversion
- operator
- reftype
- csharp10
- csharp11
- csharp7.3
- csharp8
- csharp9
- dataflow
- async
- callablereturnsarg
- external-models
- library
- tuples
- types
- definitions
- delegates
- dispatch
- enums
- events
- expressions
- extension-method-call
- fields
- frameworks
- EntityFramework
- sql
- system
- Dispose
- Equals
- generics
- indexers
- members
- methods
- namespaces
- nestedtypes
- operators
- overrides
- parameters
- properties
- regressions
- tostringwithtypes
- types
- unification
- utils
- query-tests
- API Abuse
- IncorrectCompareToSignature
- NonOverridingMethod
- Dead Code/Tests
- Documentation
- Likely Bugs/InconsistentCompareTo
- Security Features
- CWE-285/MissingAccessControl/MVCTests
- CWE-639/MVCTests
- Stubs
- All
- Minimal
- References
- Telemetry
- LibraryUsage
- SupportedExternalApis
- Useless Code/PointlessForwardingMethod
- resources/stubs/_frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- utils
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- scripts/stubs
- tools
- docs
- codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- ql-language-reference
- ql-training/query-examples/java
- reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- documentation/library-coverage
- extractor
- vendor
- golang.org/x
- mod
- internal/lazyregexp
- modfile
- module
- semver
- sys
- execabs
- tools
- go
- gcexportdata
- internal/packagesdriver
- packages
- types/objectpath
- internal
- event
- core
- keys
- label
- tag
- gcimporter
- gocommand
- packagesinternal
- pkgbits
- tokeninternal
- typeparams
- typesinternal
- ql
- consistency-queries
- change-notes/released
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- go-get-without-modules-sample
- go-mod-sample
- make-sample
- ninja-sample
- single-go-mod-and-go-files-not-under-it
- single-go-mod-in-root
- single-go-mod-not-in-root
- single-go-work-not-in-root
- two-go-mods-nested-none-in-root
- two-go-mods-nested-one-in-root
- two-go-mods-not-nested
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- change-notes/released
- experimental
- CWE-287
- examples
- CWE-321-V2
- CWE-347
- CWE-942
- frameworks
- meta/frameworks
- test
- experimental
- CWE-287
- vendor
- gopkg.in/ldap.v2
- CWE-321-V2
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- CWE-347
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- CWE-942
- vendor
- github.com
- gin-contrib/cors
- gin-gonic/gin
- library-tests/semmle/go/frameworks
- Afero
- vendor
- github.com/spf13/afero
- Beego
- vendor
- github.com/beego/beego/v2/server/web
- context
- Echo
- vendor/github.com/labstack/echo/v4
- Fiber
- vendor
- github.com/gofiber/fiber/v2
- Gin
- vendor/github.com/gin-gonic/gin
- binding
- GoKit
- Iris
- vendor
- github.com/kataras/iris/v12/context
- XNetHtml
- query-tests
- Diagnostics
- Security
- CWE-079
- CWE-681
- Summary/vendor/github.com/github/codeql-go/extractor/util
- vendor/golang.org/x/tools
- go/packages
- internal/typesinternal
- javascript
- downgrades
- externs
- extractor
- lib/typescript
- parser-tests
- src/com/semmle
- jcorn
- flow
- js
- ast
- extractor
- parser
- tests
- esnext
- input
- output/trap
- vue
- input
- output/trap
- test/com/semmle/js/extractor/test
- ql
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- frameworks
- data/internal
- internal
- security
- dataflow
- regexp
- src
- Performance
- RegExp
- Security
- CWE-327
- CWE-400
- change-notes/released
- test
- ApiGraphs/tagged-template
- library-tests
- CallGraphs/FullTest
- Constants
- DOM
- Expr
- Functions
- JSDoc/Nodes
- ModuleImportNodes
- Promises
- PropWrite
- TaintTracking
- TypeScript
- HasUnderlyingType
- ImportAssertions
- QualifiedNameResolution
- TypeAliases
- TypeAnnotations
- Types
- frameworks
- AngularJS
- controllers
- routes
- Base64
- Express
- src
- NodeJSLib
- ReactJS
- SocketIO
- fastify
- hapi
- koa
- restify
- stmts
- query-tests
- Expressions/ShiftOutOfRange
- LanguageFeatures
- ArgumentsCallerCallee
- DebuggerStatement
- Eval
- Security
- CWE-327
- CWE-770/MissingRateLimit
- tutorials/Introducing the JavaScript libraries
- java
- documentation/library-coverage
- kotlin-extractor/src/main
- java/com/semmle/extractor/java
- kotlin
- utils
- versions
- v_1_5_0
- v_1_7_0
- v_1_8_0
- v_1_9_255-SNAPSHOT
- ql
- automodel
- src
- change-notes/released
- test/AutomodelApplicationModeExtraction
- consistency-queries
- examples/snippets
- integration-tests
- all-platforms
- java
- android-sample-kotlin-build-script-no-wrapper
- android-sample-kotlin-build-script
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-kotlin-build-script
- android-sample-old-style-no-wrapper
- android-sample-old-style
- android-sample
- diagnostics/java-version-too-old
- kotlin
- annotation-id-consistency
- default-parameter-mad-flow
- external-property-overloads
- gradle_kotlinx_serialization
- logs
- nested_generic_types
- trap_compression
- linux-only/kotlin/custom_plugin
- posix-only/kotlin/generic-extension-property
- lib
- change-notes
- released
- ext
- threatmodels
- semmle/code/java
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- deadcode
- dispatch
- environment
- frameworks
- android
- apache
- camel
- google
- hudson
- jackson
- javaee
- ejb
- kotlin
- play
- spring
- struts
- os
- regex
- security
- internal
- regexp
- src
- Advisory/Java Objects
- Architecture/Refactoring Opportunities
- Complexity
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Frameworks/Swing
- I18N
- Inheritance
- Likely Typos
- Reflection
- Resource Leaks
- Statements
- Termination
- Metrics/Summaries
- Performance
- Security/CWE
- CWE-023
- CWE-079
- CWE-200
- CWE-297
- CWE-312
- CWE-319
- CWE-335
- CWE-338
- CWE-352
- CWE-367
- CWE-421
- CWE-502
- CWE-614
- CWE-676
- CWE-730
- CWE-798
- CWE-807
- CWE-833
- Violations of Best Practice
- Boxed Types
- Dead Code
- Exception Handling
- Implementation Hiding
- Magic Constants
- Naming Conventions
- Undesirable Calls
- legacy
- change-notes
- released
- experimental
- Security/CWE
- CWE-016
- CWE-020
- CWE-036
- CWE-073
- CWE-078
- CWE-089
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- CWE-295
- CWE-297
- CWE-299
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-552
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- CWE-939
- semmle/code/java/security
- meta
- frameworks
- ssa
- test
- TestUtilities
- experimental/query-tests/security/CWE-400
- kotlin/library-tests
- annotation_classes
- arrays
- call-int-to-char
- classes
- companion_objects
- controlflow
- basic
- paths
- data-classes
- dataflow
- func
- notnullexpr
- taint
- whenexpr
- enum
- exprs_typeaccess
- exprs
- extensions_recursion
- extensions
- fake_overrides
- all_java
- all_kotlin
- kotlin_calling_java
- for-array-iterators
- generic-instance-methods
- generic-methods
- generics
- inherited-callee
- inherited-collection-implementation
- inherited-default-value
- java-kotlin-collection-type-generic-methods
- java-map-methods
- java_and_kotlin
- java_properties
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmstatic-annotation
- lateinit
- maps-iterator-overloads
- methods
- multiple_extensions
- multiple_files
- operator-overloads
- parameter-defaults
- reflection
- special-method-getters
- static-method-calls
- stmts
- string-charat
- super-method-calls
- vararg
- library-tests
- JDK
- UnsafeDeserialization
- collections
- constructors
- controlflow/paths
- dataflow
- call-sensitivity
- callback-dispatch
- capture
- collections
- entrypoint-types
- fields
- inoutbarriers
- lambda
- local-additional-taint
- local-flow
- modulus-analysis
- partial
- range-analysis
- records
- state
- switchexpr
- taintgettersetter
- taintreturn
- taintsources
- taint
- threat-models
- typepruning
- defUse
- dispatch
- errorexpr
- frameworks
- JaxWs
- android
- content-provider
- external-storage
- slice
- sources
- taint-database
- widget
- apache-collections
- apache-http
- guava/handwritten
- guice
- jms
- netty/manual
- rabbitmq
- ratpack
- spring/controller
- generics
- implicit-this-type
- java7/MultiCatch
- multiply-bounded-wildcards
- printAst
- reflection
- sensitive-actions
- ssa-large
- ssa
- typeaccesses
- typeflow
- types/record-classes
- varargs
- query-tests/security
- CWE-089/semmle/examples
- CWE-117
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-352
- CONSISTENCY
- CWE-502
- CWE-927
- stubs
- apache-mina-sshd-2.8.0/org/apache/sshd/common/util/threads
- springframework-5.3.8/org/springframework/security/config/annotation/web
- builders
- configurers
- misc
- codegen
- generators
- lib
- loaders
- templates
- test
- scripts
- library-coverage
- models-as-data
- suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- internal
- security/regexp
- src
- Security
- CWE-327
- CWE-730
- change-notes
- released
- test
- 2/library-tests/six
- 3/library-tests
- modules/entry_point
- six
- experimental
- dataflow
- calls
- consistency
- coverage
- module-initialization
- strange-essaflow
- tainttracking
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- typetracking
- variable-capture
- library-tests
- CallGraph-implicit-init
- foo_explicit
- bar
- foo
- bar
- not_root/baz
- bar
- CallGraph
- meta/debug
- query-tests/Security/CWE-022-TarSlip
- library-tests
- ApiGraphs/py3
- PointsTo/regressions/wrong/module-imports/conflict-stdlib
- frameworks
- django-orm
- joblib
- numpy
- pandas
- query-tests/Security
- CWE-327-BrokenCryptoAlgorithm
- CWE-502-UnsafeDeserialization
- ql
- buramu
- extractor
- ruby
- ql
- lib
- change-notes
- released
- codeql/ruby
- dataflow
- internal
- frameworks
- core
- data/internal
- internal
- security
- regexp
- typetracking
- internal
- src
- change-notes/released
- experimental/cwe-347
- examples
- queries
- modeling
- internal
- security
- cwe-1333
- cwe-134
- cwe-327
- cwe-912
- test
- library-tests
- dataflow
- array-flow
- hash-flow
- local
- params
- type-tracker
- frameworks/graphql
- app/graphql/types
- variables
- query-tests
- experimental/cwe-347
- security
- cwe-078/CommandInjection
- cwe-327
- scripts
- swift
- downgrades
- 04ef9ecaa9e06a587f252f147462861e3d32846a
- 556e495d498c9c01286088785b590a7e80f0bb0b
- 7c17e1f4b2d30f2da05bfa667c621ddd418eb151
- c0db61944f46ba5507f207ec2b1cff77ad0529a1
- fcc7b497930add320fabeed9b228b264bc847ae6
- extractor
- infra
- mangler
- translators
- integration-tests
- ql
- lib
- change-notes
- released
- codeql/swift
- controlflow
- internal
- dataflow/internal
- elements
- decl
- expr
- pattern
- stmt
- type
- frameworks
- SQL
- StandardLibrary
- generated
- decl
- expr
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
3,386 files changed
+238226
-94992
lines changedLines changed: 23 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + |
Lines changed: 24 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
| 12 | + | |
| 13 | + | |
12 | 14 |
| |
13 | 15 |
| |
14 | 16 |
| |
15 | 17 |
| |
16 | 18 |
| |
17 | 19 |
| |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
18 | 24 |
| |
19 | 25 |
| |
| 26 | + | |
20 | 27 |
| |
21 | 28 |
| |
22 | 29 |
| |
23 | 30 |
| |
24 |
| - | |
25 |
| - | |
26 | 31 |
| |
27 |
| - | |
28 |
| - | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
29 | 42 |
| |
30 |
| - | |
31 |
| - | |
32 | 43 |
| |
33 |
| - | |
34 |
| - | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
| 37 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
91 | 91 |
| |
92 | 92 |
| |
93 | 93 |
| |
94 |
| - | |
| 94 | + | |
95 | 95 |
| |
96 | 96 |
| |
97 | 97 |
| |
|
Lines changed: 24 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
89 | 89 |
| |
90 | 90 |
| |
91 | 91 |
| |
92 |
| - | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
93 | 95 |
| |
94 | 96 |
| |
95 | 97 |
| |
96 | 98 |
| |
97 | 99 |
| |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + |
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
9 |
| - | |
| 9 | + | |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
| 32 | + | |
32 | 33 |
| |
33 | 34 |
| |
34 | 35 |
| |
|
Lines changed: 0 additions & 16 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
498 | 498 |
| |
499 | 499 |
| |
500 | 500 |
| |
501 |
| - | |
502 |
| - | |
503 |
| - | |
504 |
| - | |
505 |
| - | |
506 |
| - | |
507 |
| - | |
508 |
| - | |
509 |
| - | |
510 |
| - | |
511 |
| - | |
512 |
| - | |
513 |
| - | |
514 |
| - | |
515 |
| - | |
516 |
| - | |
517 | 501 |
| |
518 | 502 |
| |
519 | 503 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
145 | 145 |
| |
146 | 146 |
| |
147 | 147 |
| |
148 |
| - | |
| 148 | + | |
149 | 149 |
| |
150 |
| - | |
| 150 | + | |
151 | 151 |
| |
152 | 152 |
| |
153 | 153 |
| |
|
Lines changed: 19 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + |
0 commit comments